# Docker / Helm overwriting custom (certificate) configuration

**URL:** <https://forum.opensearch.org/t/docker-helm-overwriting-custom-certificate-configuration/21158>\
**Category:** Security\
**Tags:** troubleshoot, documentation\
**Created:** [September 5, 2024, 11:32am UTC](https://forum.opensearch.org/t/docker-helm-overwriting-custom-certificate-configuration/21158 "2024-09-05T11:32:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![M\_Schmid](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@M\_Schmid](https://forum.opensearch.org/u/M_Schmid)\
**Post date:** [September 5, 2024, 11:32am UTC](https://forum.opensearch.org/t/docker-helm-overwriting-custom-certificate-configuration/21158/1 "2024-09-05T11:32:37Z")

</div>

**This is already the solution for the problem outlined in here.**

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
OpenSearch: 2.15.0  
Helm Chart: 2.21.0

**Describe the issue** :  
Opensearch Helm chart provides the ability to configure the `opensearch.yml` that hold configuration values. See [helm-charts/charts/opensearch/values.yaml at 4253842c1e4d3ac6d4aee294e905c1f20469adc2 · opensearch-project/helm-charts · GitHub](https://github.com/opensearch-project/helm-charts/blob/4253842c1e4d3ac6d4aee294e905c1f20469adc2/charts/opensearch/values.yaml#L49)

One would assume that mounting custom keys and certificates anywhere under `config/` and changing the `opensearch.yml` accordingly would make OpenSearch use these files.

Like so

```auto
config:
  opensearch.yml: |
    plugins:
      security:
        ssl:
          transport:
            pemcert_filepath: certs/tls.crt
            pemkey_filepath: certs/tls.key
            pemtrustedcas_filepath: certs/ca.crt
            enforce_hostname_verification: false
          http:
            enabled: true
            pemcert_filepath: certs/tls.crt
            pemkey_filepath: certs/tls.key
            pemtrustedcas_filepath: certs/ca.crt
[...]

```

But looking at the `/usr/share/opensearch/config/opensearch.yml` inside the container it shows a demo configuration, that gets appended to the contents defined in the helm chart values above. Similar to

```auto
    plugins:
      security:
        ssl:
          transport:
            pemcert_filepath: esnode.pem
            pemkey_filepath: esnode-key.pem
            pemtrustedcas_filepath: root-ca.pem
            enforce_hostname_verification: false
          http:
            enabled: true
            pemcert_filepath: esnode.pem
            pemkey_filepath: esnode-key.pem
            pemtrustedcas_filepath: root-ca.pem

```

This is effectively overwriting all efforts to make opensearch use the custom tls files.

But why?

There is an undocumented environment variable `DISABLE_INSTALL_DEMO_CONFIG` that is used in the `entrypoint.sh` of the docker image that appends this demo configuration.

> <https://github.com/opensearch-project/opensearch-build/blob/a17589a4fa14c1328c5717c6fc3f427dae288794/docker/release/config/opensearch/opensearch-docker-entrypoint-2.x.sh#L40>

Setting `DISABLE_INSTALL_DEMO_CONFIG: true` leaves `opensearch.yml` with only the data you set up in the chart values.

**Please document this option! Ideally in the chart and in the image itself.**

**Configuration** :  
--

**Relevant Logs or Screenshots** :  
--

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [September 5, 2024, 11:38am UTC](https://forum.opensearch.org/t/docker-helm-overwriting-custom-certificate-configuration/21158/2 "2024-09-05T11:38:09Z")

</div>

Hi @M_Schmid, Thanks for sharing your findings here is some info I found on GitHub: [Duplicated security config in opensearch.yml · Issue #564 · opensearch-project/helm-charts · GitHub](https://github.com/opensearch-project/helm-charts/issues/564) looks like it’s related and might be a work in progress.

best,  
mj

---

<div class="post-metadata">

**Author:** ![M\_Schmid](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@M\_Schmid](https://forum.opensearch.org/u/M_Schmid)\
**Post date:** [September 5, 2024, 11:46am UTC](https://forum.opensearch.org/t/docker-helm-overwriting-custom-certificate-configuration/21158/3 "2024-09-05T11:46:26Z")

</div>

Thanks, you’re absolutely right, that’s the behavior here.

Turns out there is in fact a note about this: [helm-charts/README.md at main · opensearch-project/helm-charts · GitHub](https://github.com/opensearch-project/helm-charts/blob/main/README.md#notes-about-default-installation)

But to be honest: WTF? 😃
